Lateral movement getting blocked by traditional methods?
@werdhaihai just dropped research on a new lateral movement technique using Windows Installer Custom Action Server, complete with working BOF code. ghst.ly/4pN03PG
I'm using GROK (AI) to do what I've done in Excel to make a report of how ransomware incidents typically play out with common techniques for 4 stages.
stage 1 - credential access
stage 2 - network access
stage 3 - Escalation
stage 4 - Impact
I've created an excel version based…
Zscaler ThreatLabz has published a new technical analysis of the Russia-aligned threat group COLDRIVER and the updates they have made to their arsenal. The analysis covers the group’s latest tooling, including a new downloader we named BAITSWITCH along with a new PowerShell-based…
🚨The #ClickFix campaign is rising. Threat actors are using sophisticated domains (e.g. consent.oogle[.]it) to deceive victims.
Analysis of Fake Captcha code revealed a PowerShell command pointing to wezimin[.shop/blindspot.mp3 – not an MP3, but an obfuscated .js script.
Pleased to share I was invited on and spoke to the RiskyBiz Podcast about the BlackBasta Leaks with @campuscodi!
🎙️ risky.biz/RBTALKS6/
The leaks represent a great opportunity for cybercrime analysts to understand how these ransomware gangs operate #FOR589@sansforensics
🚨 How was Black Basta structured? What were its members’ roles? How did its infrastructure operate?
Leaked chats reveal a highly organized ransomware group with defined leadership, internal teams, and external affiliates.
More in my article ⬇️
cybercrimediaries.com/post/black-bas…
AS promised , i am done with writing my blog post about #GOZI aka #ISFB, where i went in the depth of analyzing the first loader,uncovering the config decryption routine ,showcasing #malware self-injection ,and the extraction of the 2nd stage.
blu3eye.gitbook.io/malware-insigh…
U may notice that new #Lumma Stealer C2 are Cloudflare blocked
You just need to setup the correct User-Agent (the one that builds use):
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36
idk if this is a new feature
U may notice that new #Lumma Stealer C2 are Cloudflare blocked
You just need to setup the correct User-Agent (the one that builds use):
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36
idk if this is a new feature https://t.co/EuKrBD2CQR
🔥#InvestigationPath#Exfiltration 🔥 🧵1
1⃣Reconnaissance activity performed:
EcMeun.exe➡️d4cae9981946b6e2fb1cf52eedd10261
2⃣TA opened an elevated command prompt via the EcMenu.exe utility using /RunAdmin from a directory containing rclone tool.
Releasing WebcamBOF📸
github.com/CodeXTF2/Webca…
Webcam capture capability for Cobalt Strike as a BOF, with in-memory download options (as a file or screenshot). USB webcams supported (at least mine is)
Remind me never to use the MF API in BOFs again😭
(god i hate this codebase)
⚡️One Million Dorks - A repository with text files containing a million dorks for finding potentially vulnerable web pages and sensitive data (in Google and other search engines). Can be used with various automation tools.
🎯github.com/HackShiv/OneDo…#bugbounty#cybersecurity
4K Followers 287 FollowingExpert on cyber threats detection and response. Fast detect and respond to threats with high-fidelity, efficient, actionable security intelligence.
189 Followers 495 FollowingLove/hate relationship with malware that leads to drinking a lot of bourbon. Thoughts are my own and you won't want them anyways.
83 Followers 32 FollowingAsk yourself if what you are doing today is getting you closer to where you want to be tomorrow. Business Administration Real estate management 📉
8K Followers 6K Following#InfoSec professional, husband & father of two (in random order). #BlueTeam #DFIR #APT #CTI #RedTeaming #BSidesZH (RT/Likes ≠ endorsement) 👀➡️#MalwareChallenge
4K Followers 921 Followinghttps://t.co/9I6nRUiFjm is a service that provides threat intelligence data about observed network scanning and cyber attacks.
1K Followers 6K Followingसियावर रामचंद्र की जय पवनसुत हनुमान की जय I tweet about politics•geopolitics•defence and offensive replies to liberandu/leftist-islamic brigade.
52K Followers 6K FollowingWe cover military and political strategies in the Arab and Middle Eastern countries, tracking news, security, and military movements on land, sea, and air.
1K Followers 423 FollowingThreat Intel Researcher.
Opinions are mine.
Special thanks to @censysio , @ValidinLLC & @ReversingLabs for making my research easier.
3K Followers 1K FollowingLearner | CTF with @PwsecTeam | Amature Astronomer |
Tip:- In the world where you can be anything, be Kind.|
Words are of my own, and not of my employer
4K Followers 774 Followingit security & cyber guy, research @ https://t.co/M5rsSPPPWy, friendly, swiss | Opinions are my own | also https://t.co/v6cAL269P7
733 Followers 283 FollowingHack and Hack again..
Won Top 3 in the HackTheBox ValentinesDay Tournament.
Won Top 100 in the HacktheBox Cyber Apocalypse event.
11K Followers 1K FollowingCensys is the source for real-time Internet intelligence and actionable threat insights for governments, F500 companies, and leading threat intel providers
4K Followers 359 FollowingSkating fraud and bug preservationist. Shell smuggling business in the past. I once had a Pwnie. Bon pour l'Orient. New(er) Labour.
301K Followers 43 FollowingLeader of the Opposition, 17th WBLA. 3rd Term MLA; @BJP4India MLA from Nandigram.
Previously Cabinet Minister; Govt of WB & 2 term MP (Lok Sabha) from Tamluk.